

Privacy Statement for Vevd AS
Vevd AS processes personal data in connection with the operation of the website vevd.ai, sales and marketing, delivery of client engagements and general administration of the business. This statement explains what data we process, why we process it, how long we keep it and what rights you have.
Last updated: 11 August 2026
1. Data controller
Vevd AS is the data controller for the processing described in this statement.
| Company | Vevd AS |
| Organisation number | 837 377 862 |
| Address | Tordenskiolds gate 2, 0160 Oslo, Norway |
| hi@vevd.ai | |
| Contact | Lars Kvinge, CEO |
Vevd is not required to appoint a data protection officer and has not done so. Please direct any privacy questions to the address above.
2. Our two roles
We process personal data in two distinct roles.
As data controller. We determine the purposes and means of the processing ourselves. This applies to the website, sales and marketing, client administration, supplier management and recruitment. This statement covers that processing.
As data processor. In client engagements, such as workflow mapping, we process personal data on behalf of the client and on the client’s instructions. The client is then the data controller, and the processing is governed by a separate data processing agreement. The client’s own privacy statement applies to that data.
3. What data we process
3.1 Visitors to vevd.ai
We process technical data such as IP address, browser type, device, time of visit and pages viewed. The purpose is to deliver and secure the website and to understand how it is used.
Legal basis: legitimate interest in secure and stable operation, GDPR Article 6(1)(f). For cookies that are not strictly necessary, the basis is your consent. See section 4.
Retention: 12 months for server logs, then deletion.
3.2 Enquiries
When you contact us through the contact form, by email, by phone or on LinkedIn, we process your name, contact details, employer and the content of the enquiry.
Legal basis: legitimate interest in responding to enquiries, Article 6(1)(f), or steps taken prior to entering into a contract, Article 6(1)(b).
Retention: until the enquiry has been dealt with, normally no more than 12 months, unless it leads to a client relationship.
3.3 Sales and outbound marketing
We contact people in professional roles at organisations we believe may benefit from our services. We process name, job title, employer, publicly available profile information, business contact details and a log of contact and responses.
The data is collected from publicly available sources, including LinkedIn, company websites, the Norwegian Register of Business Enterprises and similar open registers.
Legal basis: legitimate interest in marketing our services to relevant organisations, Article 6(1)(f). We have assessed that this interest outweighs the impact on the individual, because the contact takes place in a professional context, concerns the organisation’s affairs rather than private matters, involves a limited set of data, does not involve special categories of personal data, and because opting out is straightforward.
You may object to this processing at any time, see section 9. We will then record an opt-out so that you are not contacted again.
Retention: up to 24 months after the last contact, or until you opt out. Opt-out records are kept for as long as necessary to honour them.
3.4 Clients and client contacts
We process name, job title, contact details, correspondence and data relating to the contract, delivery and invoicing.
Legal basis: performance of a contract, Article 6(1)(b), legitimate interest in client management, Article 6(1)(f), and legal obligation for accounting records, Article 6(1)(c).
Retention: for the duration of the client relationship and then up to 3 years. Accounting records are kept for five years after the end of the financial year in accordance with the Norwegian Bookkeeping Act.
3.5 Suppliers and partners
We process contact details for contact persons at suppliers and partners in order to manage the relationship.
Legal basis: performance of a contract and legitimate interest, Article 6(1)(b) and (f).
Retention: for the duration of the relationship and then up to 3 years.
3.6 Job applicants
We process applications, CVs, references and interview notes.
Legal basis: steps taken prior to entering into a contract, Article 6(1)(b). If we wish to keep an application on file for future openings, we ask for consent, Article 6(1)(a).
Retention: deleted once the recruitment process is closed, unless you consent to longer storage, normally up to 12 months.
3.7 Personal data in client engagements
When mapping workflows, we may encounter personal data in the client’s systems and processes, for example the names of employees performing tasks, approvers in an approval chain or the content of case handling.
We work on the principle of data minimisation. We record roles and functions rather than named individuals wherever possible, and we do not extract more data than the engagement requires. This processing is carried out on the client’s instructions and under a data processing agreement.
4. Cookies
The website is built in Framer. Framer’s built-in visitor statistics are cookie-free and set no persistent identifiers.
In addition, we use Google Analytics to measure use of the website. Google Analytics sets the following cookies:
| Cookie | Purpose | Duration |
|---|---|---|
| _ga | Distinguishes visitors | 24 months |
| _ga_DNYP30EMXJ | Maintains session state | 24 months |
You can delete or block cookies in your browser, and you can opt out of Google Analytics across all websites by installing Google’s browser opt-out add-on.
5. Who we share data with
We do not sell personal data. We share data with suppliers who process it on our behalf, and we have a data processing agreement with each of them.
| Supplier | Purpose | Location |
|---|---|---|
| Framer | Website hosting and operation | EEA and USA |
| Google Analytics | Website visitor statistics | EEA and USA |
| Google Workspace | Email, calendar and file storage | EEA and USA |
| Google Cloud Firestore | Database and client records | EEA and USA |
| Tripletex | Accounting and bookkeeping system | EEA |
We do not enter personal data from client engagements into AI tools.
We may also disclose data where we are legally required to do so, or to advisers where necessary, for example our auditor or legal counsel.
6. Transfers outside the EEA
Some of our suppliers process data outside the EEA, mainly in the United States. Transfers are based on the European Commission’s Standard Contractual Clauses, Article 46(2)(c), or certification under the EU-US Data Privacy Framework, together with supplementary measures where required. You may request a copy of the transfer safeguards by contacting us.
7. Security
We have technical and organisational measures in place to protect personal data, including access control on a need-to-know basis, two-factor authentication, encryption in transit and at rest, logging, use of suppliers with a documented security level, and procedures for handling incidents. In the event of a personal data breach, we notify the Norwegian Data Protection Authority within 72 hours where required, and the individuals concerned if the breach poses a high risk.
8. Automated decisions and use of AI
We use AI tools to support our analysis and mapping work. We do not make automated decisions that produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22. All assessments and recommendations are reviewed by a person at Vevd.
9. Your rights
You have the right to request access to the data we hold about you, to have inaccurate data corrected, to have data erased, to request restriction of processing, to receive data you have provided in a machine-readable format (data portability), to object to processing based on legitimate interest, including direct marketing, and to withdraw consent where processing is based on consent.
Requests should be sent to hi@vevd.ai. We normally respond within 30 days, free of charge. We may ask you to verify your identity where necessary to ensure that data is not disclosed to the wrong person.
10. Complaints
If you disagree with how we process personal data, we would appreciate hearing from you first. You always have the right to lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet), Postboks 458 Sentrum, 0105 Oslo, postkasse@datatilsynet.no.
11. Changes
We may update this statement following changes to our services, systems or applicable law. The current version is always available at vevd.ai. Where material changes are made, we will notify those affected where practically possible.
This is a translation of the Norwegian version of our privacy statement. In the event of any discrepancy, the Norwegian version prevails.
